CVE-2019-17003
- EPSS 0.41%
- Veröffentlicht 16.02.2023 22:15:10
- Zuletzt bearbeitet 19.08.2026 15:30:33
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
CVE-2022-38474
- EPSS 0.39%
- Veröffentlicht 22.12.2022 20:15:36
- Zuletzt bearbeitet 19.08.2026 15:29:21
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has be...
CVE-2022-31746
- EPSS 0.41%
- Veröffentlicht 22.12.2022 20:15:30
- Zuletzt bearbeitet 19.08.2026 15:30:33
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
CVE-2022-26486
- EPSS 2.35%
- Veröffentlicht 22.12.2022 20:15:22
- Zuletzt bearbeitet 19.08.2026 15:29:21
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox ...
CVE-2022-26485
- EPSS 13.8%
- Veröffentlicht 22.12.2022 20:15:22
- Zuletzt bearbeitet 19.08.2026 15:29:21
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3...
CVE-2021-29993
- EPSS 0.7%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 19.08.2026 15:29:21
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 9...
CVE-2020-26977
- EPSS 0.85%
- Veröffentlicht 07.01.2021 14:15:12
- Zuletzt bearbeitet 19.08.2026 15:29:21
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are una...
CVE-2020-26975
- EPSS 0.86%
- Veröffentlicht 07.01.2021 14:15:12
- Zuletzt bearbeitet 19.08.2026 15:29:21
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only a...
CVE-2020-26964
- EPSS 0.91%
- Veröffentlicht 09.12.2020 01:15:13
- Zuletzt bearbeitet 19.08.2026 15:29:21
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web co...
CVE-2020-26957
- EPSS 0.54%
- Veröffentlicht 09.12.2020 01:15:13
- Zuletzt bearbeitet 19.08.2026 15:29:21
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are...